esm

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This file is a skill/README for a protein modeling SDK. It describes expected capabilities (generation, embeddings, structure prediction), legitimate install paths (pip), and use of a vendor Forge API requiring an API token. I found no code-level indicators of malware, backdoors, download-and-execute chains, or credential-harvesting behavior in the provided text. Main concerns are standard supply-chain risks from installing packages and fetching model weights, potential privacy/biosecurity sensitivity of uploading sequences/structures to a cloud service, a minor documentation inconsistency ('uv pip install') and use of a URL shortener. Overall the document appears functionally coherent with its stated purpose but requires normal operational caution when installing packages and when sending biological sequence/structure data to third-party cloud services.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/K-Dense-AI%2Fclaude-scientific-skills%2Fesm%2F@4e7f996530f86b9b07cc534c9284db9413089996